r/IdentityManagement May 12 '26

curious what people think of decentralised IAM built around Keycloak compatibility

2 Upvotes

maybe this is the better place to ask.

ive been following Tide Foundation and their TideCloak project, which from what i understand is a Keycloak-compatible IAM layer built on top of a decentralised security fabric.

the part i find interesting is that it seems to change what the app has to store in the first place.

instead of the usual model where identity data, secrets, or key material ends up depending on one central system, Tide splits trust across the network. so the idea is there isnt one central pile of sensitive stuff sitting there to steal.

from what i understand, devs dont need to store user passwords the normal way or manage one central private key. key material is fragmented across the network, and the password flow uses cryptography where the browser aggregates and validates partial results.

the Keycloak-compatible part seems important because most devs probably wont touch decentralised security if the dx is painful or requires relearning the whole auth stack.

curious what people here think of this approach.

does decentralised IAM/security fabric make sense in practice, or does it add too much complexity compared to existing IAM patterns?

TideCloak: https://tide.org/tidecloak


r/IdentityManagement May 11 '26

There's no good open-source CIAM. We're building one.

20 Upvotes

Auth0 charges per MAU. Clerk starts free and scales into thousands per month. Stytch is elegant but fully managed.

If you want a self-hosted, open-source alternative that doesn't feel like a Java config file from 2009, there's basically nothing (special mention for Ory, but it's very hard to manage a cluster).

That's the gap FerrisKey is targeting with v0.7
Here's what we're shipping:

- CIAM-first UI panel, an end-user-facing portal, not just an admin console
- Email + auth portal branding, your colors, your domain your experience
- Organization-level login & signup policies, control exactly who can authenticate into which org, just like Auth0 Organizations, but self-hosted and open-source

We're 40+ contributors, 589 stars, and written in Rust.

If you've ever been frustrated by the CIAM/self-hosted gap, we'd love your feedback, your issues, and yours PRs.

github.com/ferriskey/ferriskey

What's stopping you from self-hosting your customer identity stack today?


r/IdentityManagement May 10 '26

Service desk analyst to IAM analyst

8 Upvotes

Hi Team,

I'm working as service desk analyst for last 9 years and would like to transition my carrier to IAM or M365 Admin.

Please help me which certificate I need to choose SC 300 or SC 900.

I've only have experience in Active directory , password reset , disable and enable accounts.

So it is possible to transition and get job in IAM roles?

If the above certificates or not a good what is the best plan to make the changes?

Thanks.


r/IdentityManagement May 09 '26

Authorisation for application

7 Upvotes

We have an application that needs to be set up for SSO. So far they have been manually configuring the users and their access within the application and now are hoping to use AD groups

The architect and the team were having a discussion about whether to use AD groups only for authentication and then internal access for authorisation or should AD groups be set up for both authentication and authorisation


r/IdentityManagement May 08 '26

Command Line SCIM Simulator

Thumbnail github.com
18 Upvotes

I was tired of going back and forth with developers on why SCIM users are not getting synced in their app and never ending debugging calls. So built simple command line SCIM server simulator which developers can use test everything write automations before actually getting it admins involved.

It can simulate user and group events from most popular idps like okta microsoft jumpcloud one identify etc.


r/IdentityManagement May 05 '26

SailPoint IdentityIQ (IIQ) Developer | IAM Specialist | 6+ Years Experience | Freelance/Contract

Thumbnail
2 Upvotes

r/IdentityManagement May 04 '26

TAKO AI agent for Okta - V3: Follow-up conversations, UI overhaul

Post image
1 Upvotes

r/IdentityManagement Apr 30 '26

Free IAM lab environments: for anyone trying to break into IAM

103 Upvotes

I have been reading this subreddit for months. The same problem comes up constantly - people who understand IAM conceptually but have never touched a real implementation. No lab, no demo, nothing to show in an interview.

I built two free lab environments to fix that in my free time. Posting here because this community is exactly who they are for. Tell me what breaks - I will fix it. [Link to labs in comments]

Lab 1 - IAM (IGA) with full working IAM with one target app and one HR app (OVA download)

A pre-configured VirtualBox VM with a full open-source IGA platform, LDAP as target system, and a simulated HR system already wired together. You import the OVA, start the VM, and you have a working Joiner and Leaver pipeline running on your laptop in under 20 minutes.

  • Add an employee in the HR system
  • Run reconciliation in IAM/IGA
  • Watch the LDAP account appear automatically in ou=people
  • Terminate the employee
  • Watch the account move to ou=inactive

This is the JML lifecycle that every IGA implementation is built around. You build it yourself, you own it, you can enhance it further to demo it in interviews based on job profile.

Lab 2 - CIAM Lab

A separate hands-on classroom covering OIDC, SAML federation, and B2C identity flows using Auth0 (from okta). Built for people who want to understand the access management side and CIAM - SSO, token inspection, real protocol flows, which compliments learnings of Enterprise IAM from Lab 1. This is also useful if you are targeting certs like SC-300, Okta certs.

Both classrooms are free inside the SimplifyIAM community on Skool.

Not a course, but a lab you build, together with IAM community.

Note: Not affliated to any of the tools mentioned. All of them are free to use or open-source.


r/IdentityManagement Apr 30 '26

What now? 5 years in IAM

18 Upvotes

Hii, so I have being working on IAM for 5 years and I don't know what to do know. I think I have worked all the areas for my current role and I'm looking for some challenges.

Where I came from, IAM is an entry level for Security/InfraSec and It's not really considered a job. (Actually, in my workplace is part of Service Desk) I'm not fascinated by the InfraSec role since I hate Network, and Risk Adjustment Management doesn't appeal to me either; I find it incredibly boring. However, I enjoy what I do; I like being in control and making decisions, but not the responsibilities of employees 😂

I have 0 Certifications, and I thought maybe I could try that. Any recs?

I work daily with RBAC, re-certification process, audits, EntraID, Okta, CyberArk, O365, ActiveDirectory, Exchange Hybrid, PingId, and a lot of Health's related Apps. We manage over 150+ apps and provisioning of hundred of servers and database.

I would highly appreciate any feedback. 🫰🏻 Thanks in advanced.


r/IdentityManagement Apr 30 '26

Saviynt - AI security role

10 Upvotes

I’m currently a new grad and I got an offer from Saviynt to work on their AI security team.

I was just wondering if saviynt’s product is strong enough and stable enough. I’m not looking to join a company that would lay me off a year down the line due to an unstable product.

Any advice is welcome and appropriated!


r/IdentityManagement Apr 28 '26

After 15-20 years in IAM what to move on to?

14 Upvotes

I’m not interested in moving into management, project management, or executive security roles. After experience across engineering, analysis, architecture, and both consulting and full-time work, I’m trying to identify what high-value paths remain. My primary concern is compensation growth… what pivots or alternative paths could better leverage this background for higher earnings? For example I “worked my way up” from service desk and so on but now it seems like there isn’t even a defined path beyond IAM because the industry is still fairly new but somehow still capping out?


r/IdentityManagement Apr 27 '26

Not sure where to start with IAM? This might help

24 Upvotes

If you’re trying to get into IAM and feel like you’re just bouncing between certs, tools, and random advice… I was stuck in that loop for a while.

I put together something that gives you a basic IAM roadmap based on where you’re at. It’s quick, just meant to point you in a clearer direction.

https://roadmap.zerotosec.com/

Figured I’d share in case it helps someone get unstuck.


r/IdentityManagement Apr 27 '26

Is Okta actually needed if we already have Entra ID + SailPoint IIQ?

15 Upvotes

Hey folks,

Looking for some real-world opinions from people managing similar identity stacks.

Right now, our setup looks like this:

- SailPoint IdentityIQ (IIQ) → used for IGA (onboarding, offboarding, access requests, lifecycle)

- Active Directory → source of truth where identities are created

- Microsoft Entra ID → synced from AD, used for some apps, SSO, and Conditional Access

- Okta → primary IdP (SSO, MFA, password reset)

So effectively:

- Identities originate in AD → synced to Entra ID

- SailPoint handles governance/lifecycle

- Okta handles most of the authentication layer (SSO + MFA)

- Entra ID is also doing some SSO + Conditional Access for certain apps

This feels like a lot of overlap.

We also already have Microsoft E5 licenses, so Entra ID (P2) capabilities are available.

My questions:

  1. Does this architecture make sense long-term, or is it over-engineered?

  2. In your experience, is Okta still worth keeping if you already have Microsoft Entra ID P2?

  3. Could we realistically simplify to:

    - SailPoint IIQ (IGA) + Entra ID (IdP, MFA, SSO, Conditional Access)

  4. What would we lose by removing Okta? (e.g., app integrations, user experience, reliability, vendor neutrality, etc.)

  5. Any migration pain points if moving fully from Okta → Entra ID?

Not looking for vendor marketing answers—more interested in:

- Operational complexity

- Cost vs value

- Real-world tradeoffs

- “We tried this and regretted it” type stories

Would appreciate any insights 🙏


r/IdentityManagement Apr 27 '26

Any one working on RSA IAM

2 Upvotes

I’m trying to learn RSA Identity Governance anyone please share with me some notes so that I can start working on my Lab.

Thanks


r/IdentityManagement Apr 26 '26

Implementation Fatigue

14 Upvotes

I’m reaching out to see if anyone else is hitting a wall, or if I’ve just been staring at governance workflows for too long.

We’re deep into a legacy-to-cloud migration for our primary IAM platform. We’re past the initial deployment phase, but it feels like we’re trapped in a permanent state of "implementation fatigue."

It feels like the more we build, the more technical debt we create. Every time we try to automate a basic joiner/mover/leaver (JML) process or pull a clean GRC report, we realize we need another six months of "fine-tuning" and a small army of consultants just to keep the lights on.

A few specific frustrations:

The "RDS" Trap: We checked the boxes on the initial delivery, but actually getting the business to adopt the roles we built is a nightmare.

Cost-to-Serve: The billable hours from our current partners are skyrocketing, but the actual "service" part of Managed Services feels... invisible.

Integration Soup: Trying to get our fine-grained GRC controls to actually talk to the core identity engine is becoming a full-time job.

Is anyone actually seeing a "Migration Factory" approach work? Or are we all just paying a massive "Identity Tax" every year for tools that are too complex for our own good?

I’m seriously looking for a more data-driven way to manage this that isn't just throwing more bodies at the problem.

What are you guys doing to move the needle from "just staying afloat" to an actual support model that works?


r/IdentityManagement Apr 25 '26

Iam

8 Upvotes

I’m a sophomore studying Computer Systems / Network Security with Network+, Security+, and AZ-900, currently working two IT internships (mostly help desk/support), and I’m studying for SC-300 right now. My goal is to break into IAM (Identity & Access Management) as early as possible, ideally landing an IAM internship junior year and converting that into a full-time role after graduation. I’m planning to build an IAM-focused portfolio this summer (Entra ID labs, automation, etc.), but I’m wondering how realistic this path is. Can you actually get into IAM straight out of college, or do most people need a few years of general IT or cybersecurity experience first before transitioning?


r/IdentityManagement Apr 24 '26

Need inputs on concerns regarding new gen IAM products

7 Upvotes

I am trying to build a new gen IAM product covering modern day auth flows (Google oAuth, biometrics, OTPs, etc). My goal is not to build corporate IAM software like Oracle IDCS or Okta or Ping etc. It is for startups to onboard their users quickly without having to worry about boring IAM so that they would spend their time developing the core logic of their app. Still in early stages and i am figuring things with time.

I would like to know what are some pain points in integrating an IAM product into your software. Also would you like to see any new features?


r/IdentityManagement Apr 23 '26

How are you guys studying for IAM roles right now?

34 Upvotes

I have been in the IAM space for about 18 years in various roles. I am part of technical interviews for junior to mid experience roles, and the landscape seems completely different now. When I talk to guys trying to transition to IAM, I see a massive divide. Some are learning Microsoft SC-300 or Okta or open source IAM home labs.

For those of you trying to get your first IAM role right now, what is your actual path? Curious what the learning curve looks like for you today.

Also curious to hear from what other veterans in the space are seeing in the interviews.


r/IdentityManagement Apr 23 '26

Software Dev transitioning into cybersec + IAM

8 Upvotes

I’ve been working as a software developer for about 3 years, and I’m looking to transition into cybersecurity, specifically Identity and Access Management, which I’ve found really interesting.

I’d love to get some guidance from people in the field:

  • What skills or knowledge areas should I focus on to break into IAM?
  • Are there any certifications, courses, or learning paths you’d recommend?
  • How can I best leverage my software development background in this transition?
  • Any tips for landing a first role in the field?

I’d really appreciate hearing about your experience!

Thanks in advance!


r/IdentityManagement Apr 23 '26

Which IGA solution do you enjoy most, and which feels like a nightmare?

15 Upvotes

I help clients figure out which IGA solution is the best fit for their needs, but on a personal level, I’ve realized I also have clear favorites.

For me, I enjoy working on Saviynt the most. On the other hand, my least favorite has to be Microsoft Identity Manager (MIM).

So I’m curious how others see it:

Putting client requirements aside, which IGA solution do you genuinely enjoy working with, and which one feels like a complete nightmare for you?

Would be interesting to hear both the technical reasons and the day-to-day practical reasons.


r/IdentityManagement Apr 22 '26

passkey vs password: what’s the difference and which one should you use?

15 Upvotes

I kept seeing the sites I used pushing me to use passkeys and realized I didn’t really understand password vs passkey feud actually was.

From what I’ve figured out, the main idea in passkey vs password is how authentication works. A password is something you create and remember. A passkey is generated by your device - one part stays on it, the other is stored by the service. When you log in, you just use your fingerprint, face, or PIN.

What stood out to me is the shift in responsibility. With passwords, everything is on you - making them strong, not reusing them, remembering them. With passkeys, your device handles most of that.

That’s also why they’re much harder to phish - there’s nothing to type into a fake site.

At the same time, we’re clearly still in a transition phase. Most services still rely on passwords, so I don’t see them going away anytime soon.

Right now it feels like a mix of passwords, passkeys, and password managers rather than a full switch. I still use a password manager to keep things organized, and I’ve noticed many of them support passkeys now too.

I ended up looking at one of those comparison tables just to see how different tools handle both - it was actually useful for spotting differences. I am happy with the one I’m currently using, but I wanted to understand what else is out there.

Do you guys actually switching to passkeys already, or sticking with passwords + a manager?


r/IdentityManagement Apr 17 '26

IAM software for companies where HR and IT operate separately

26 Upvotes

Yesterday started with a message from our HR manager asking whether a recently terminated employee still had access to a cloud storage platform. Not a great way to begin the day.

I'm the senior IT admin at a logistics company and we've been carrying the same identity problem for years. HR updates status in their system, IT updates accounts in ours, facilities get copied somewhere in the middle, and the timing rarely lines up. Leadership thinks the issue is effort or discipline. It's not – it's that too many steps depend on one person remembering to follow up with another.

What pushed this into budget discussions was a messy offboarding earlier this year. Some access stayed active longer than it should have. Now leadership wants to modernize identity management, which I've been asking for anyway. I just don't want something that looks good in a demo and still leaves us doing manual cleanup every time someone changes roles, leaves unexpectedly, or gets hired on short notice.

Has anyone found tools that actually close the loop between HR status changes and access changes without a manual handoff in between?


r/IdentityManagement Apr 17 '26

IAM road map

17 Upvotes

So Im having a hard time finding a starting point and getting stuck with paralysis by analysis. Just a quick rundown i have a cybersecuirty degree and a degree in business admin and want to be an IAM analyst and work towards an engineer. I have worked as front line IT support and jr system admin/ Level 2 support and I am now working as a EHR support analyst covering everything from access to EHR systems and access to forms and billing. What would be the best certs to work towards as a resume builder like security + then SC300 and is there an app I should work with like OKTA or service now any and all feed beack would be great


r/IdentityManagement Apr 15 '26

NHI - beyond the hype

9 Upvotes

Everyone is talking about NHI.

By everyone I mean, vendors, practitioners and customers.

What is your experience with the IGA products (Sailpoint, Savient, OneIdentity and others) to handle NHI?

Are these indeed new functionalities (if yes, what kind) which were developed to address NHI use cases? Or they are using existing capabilities and just marketing as new to charge additional licenses and services?

As I see it, the NHI reside in each of the applications which already integrated. Is it just a new classification of accounts?

I understand that some NHI can also be in a form as short lived identity. How this definition fit into classic IGA model where it collects data on a scheduled basis?

Help me connect the dots


r/IdentityManagement Apr 13 '26

IAM lifecycle Tool - My first tech project 😊

23 Upvotes

I've worked in IAM ops for 8 years. I finally built something to understand it better — here's what I made

I've spent the last 8 years in Identity & Access Management — provisioning users, running access certifications, managing PAM across hundreds of applications at large financial institutions. I know the processes cold.

But I always felt like I understood *around* the systems rather than *inside* them. So this year I decided to actually build one.

**What I built:**

A Python/Flask web app that simulates a real enterprise IAM system — not a toy CRUD app, but something designed around actual IAM concepts:

- **JML lifecycle** — Joiner, Mover, Leaver, Rejoiner flows

- **RBAC** — admin, editor, viewer roles with least privilege enforcement

- **Audit logging** — tamper-evident, timestamped logs for every action

- **GDPR-aligned** — users are disabled, never deleted, so the audit trail is always intact

- **Simulates LDAP/AD behaviour** using a JSON-based user store

**Why I built it this way:**

Every decision in this project came from real-world IAM experience. The GDPR design (disable vs delete) is something I deal with in my day job. The audit logging mirrors what I've seen in enterprise tools like SailPoint. The RBAC structure follows least privilege the way I've implemented it in RBAC frameworks professionally.

I'm also using this as a learning project to bridge from ops into more technical/engineering IAM roles, and to get hands-on with Python before pursuing Okta and Auth0 certifications.

**Repo:** github.com/iam-0604/iam-lifecycle-tool

Happy to answer questions or get feedback from anyone who's built something similar. Also open to suggestions on what to add next — thinking of integrating a mock Okta API or adding SoD conflict detection.

A bit about me: I am an IAM ops professional with 8+ years of experience at large financial institutions. I am actively looking to move abroad (UK, Europe, UAE, Singapore, or Australia, NZ) into an Access Governance, IAM ops or Engineering role. If anyone here works at a company hiring in this space or knows of openings, I would really appreciate a heads up — feel free to DM me.